5
CVSSv2

CVE-2001-0557

Published: 14/08/2001 Updated: 19/12/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

T. Hauck Jana Webserver 1.46 and previous versions allows a remote malicious user to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e).

Vulnerable Product Search on Vulmon Subscribe to Product

t. hauck jana web server 1.0j

t. hauck jana web server 1.45

t. hauck jana web server 2.0_beta_1

t. hauck jana web server

Exploits

source: wwwsecurityfocuscom/bid/2703/info It is possible for a remote user to traverse the directories of a host running Jana Server Submitting a specially crafted URL using hex encoded 'double dot' sequences will reveal arbitrary directories In addition to revealing directories, this vulnerability could enable a user to obtain the cont ...